Courseiva

SC-200 Respond to security incidents Practice Question

You have detected a suspicious PowerShell command running on several workstations. The command appears to be downloading a payload from a known malicious URL. What is the most effective immediate response using Microsoft Defender for Endpoint?

⚠ Common exam trap

Watch out — candidates often choose a reactive, manual investigation step (like Live Response) or a broad configuration change (like ASR rules) instead of recognizing that a custom indicator provides an immediate, automated, and organization-wide block that stops the attack at the network layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the URL to the custom threat indicator list in Microsoft Defender for Endpoint.

Adding the URL to the custom threat indicator list in Microsoft Defender for Endpoint is the most effective immediate response because it creates a block indicator that applies to all endpoints in the organization. This action prevents any further downloads from that malicious URL across all workstations, stopping the attack in its tracks without disrupting user productivity or requiring manual intervention on each machine.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add the URL to the custom threat indicator list in Microsoft Defender for Endpoint.

    Why this is correct

    Adding the URL as a custom threat indicator with the action 'Alert and block' creates an immediate, environment-wide deny for that address. Defender for Endpoint enforces URL/domain indicators through Windows Defender SmartScreen and network protection, so any onboarded endpoint attempting to reach the URL is blocked before the response, not after. This targeted action stops further downloads without broad disruption to legitimate PowerShell or other workloads.

  • ✗

    Quarantine the affected workstations.

    Why it's wrong here

    Quarantining affected workstations is a device isolation action that disconnects them from the corporate network, but it leaves other endpoints with no protection against the same malicious URL. It is a reactive, high-impact step that interrupts user productivity and can also hinder the ability to collect additional evidence because the isolated device may lose communication with Defender for Endpoint. The immediate priority should be removing the URL as a reachable target, not disabling a handful of already-compromised machines.

  • ✗

    Enable attack surface reduction rule to block PowerShell scripts.

    Why it's wrong here

    Enabling an attack surface reduction (ASR) rule to block PowerShell scripts would not block the specific URL and would have a broad, behavioral effect on all script execution. ASR rules are policy-based detections that can generate false positives and may interfere with legitimate administrative scripts, and they do not retroactively terminate an already-running PowerShell process. Because the malicious download is tied to a URL, a custom threat indicator gives much greater precision than a broad script-blocking rule.

  • ✗

    Initiate a Live Response session to investigate each workstation.

    Why it's wrong here

    Live Response is an interactive digital forensics and remote remediation session that allows an analyst to inspect processes, files, and persistence mechanisms on a single endpoint. While useful for understanding the extent of the compromise, it does not publish any blocking indicator, so the URL remains reachable from every other workstation while the investigation proceeds. Starting with Live Response instead of a URL indicator block wastes time during an active IOC-based attack and leaves the organization exposed.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.